1. Introduction
Cwoted Inc. ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our platform at cwoted.com ("the Service").
2. Information We Collect
Information you provide:
- Account information: name, email address, password (hashed)
- Business information: business name, phone, email, address, logo
- Client information: names, emails, phone numbers, addresses you enter
- Estimate data: line items, pricing, notes, and proposal content
- Electronic signatures: typed names and drawn signatures from your clients
- Payment information: processed by Stripe; we do not store card numbers
Information collected automatically:
- Usage data: pages viewed, features used, timestamps
- Device information: browser type, operating system, screen resolution
- IP address: used for rate limiting, security, and fraud prevention
- Proposal tracking: when a client views, accepts, or declines a proposal
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process payments and manage subscriptions
- To send transactional emails (welcome, password reset, proposal notifications)
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations
- To provide customer support
We do not sell your personal information to third parties.
4. How We Share Your Information
We share your information only in the following circumstances:
- With your clients: When you send a proposal, your business name, contact details, and estimate content are shared with the recipient.
- Service providers: We use Stripe for payment processing, Resend for transactional email delivery, and may use Sentry for error monitoring. These providers process data on our behalf under contractual obligations.
- Legal requirements: We may disclose information if required by law, court order, or governmental request.
- Business transfers: In the event of a merger, acquisition, or asset sale, your information may be transferred as part of the transaction.
5. Data Storage and Security
Your data is stored in secure PostgreSQL databases hosted in the United States. We implement industry-standard security measures including:
- Passwords hashed with bcrypt (12 rounds)
- HTTPS encryption for all data in transit
- Rate limiting on authentication endpoints
- Security headers (X-Frame-Options, CSP, HSTS)
- Regular security reviews
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law. Anonymized, aggregated data may be retained indefinitely for analytics.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete data
- Deletion: Request deletion of your account and data
- Export: Receive your data in a portable format
- Objection: Object to certain processing of your data
To exercise any of these rights, contact us at privacy@cwoted.com.
8. Cookies
We use essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Our session cookies are HTTP-only and secure.
9. Children's Privacy
Cwoted is not intended for use by children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. International Data Transfers
Your data may be processed in the United States. By using the Service, you consent to the transfer of your data to the U.S. We take steps to ensure your data receives an adequate level of protection.
11. California Privacy Rights (CCPA)
California residents have additional rights including the right to know what personal information is collected, the right to deletion, and the right to opt-out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@cwoted.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top reflects the most recent revision.
13. Contact Us
For privacy-related questions or requests, contact us at:
Cwoted Inc.
Email: privacy@cwoted.com